Solved

ASP and SQL

Posted on 1998-12-08
2
177 Views
Last Modified: 2010-03-19
It's with regards to the ASP, and session vairables.
I am doing a Web site where it's security enforced.It's similiar in the project you assigned us.  A user logs in and from that login we determine was information they are allowed to see and what they can access.  So reference to the login variable is gonna be needed all throughout
the pages.  So session variables are the way to go right?  But session variables don't last long...(default is 20) I am gonna need it for more than that and well all I have to do is set the timeout for the session to be a larger number.  That will do it won't it?  Pretty sure it will
providing the timeout period is longer right?  I would be able to talk to different pages within a frameset and the session variable would still be alive right?  Is this my best approach or is there a better option.
Thanks for any HELP.

0
Comment
Question by:lobos
2 Comments
 
LVL 28

Expert Comment

by:sybe
ID: 1092157
The sessionvariables "die" x minutes after the last user's activity. So they won't die when a user is visiting your website and asking for pages for about 2 hours.
Sessionvariables are bound to cookies, so the browser has to accept cookies. I am not sure how "hack-resistant" cookies are, so if your information is very sensitive, you might want to use another solution then session-variables (for example NT-security, you can ask for login-name with ASP).

About this "hacking": I have never really tried to do it. But I noticed that ASP-cookies have a code that is given out in a certain order to new visitors. So if visitor A gets cookie "ASP-4565421" visitor be would get "ASP-4565422". Someone could try to change the value of the cookie in his browser and get the security of another user.

Maybe it is possible to make the ASP-cookies be more random, I haven't looked for it. I solve possible security stuff through NT-security and use cookies (and sessionvariables) only for non-sensitive things.
0
 

Accepted Solution

by:
ny_sky earned 20 total points
ID: 1092158
If Transaction Server is a possibility then you can utilize the role assignments for a given package.  You can add NT groups to each package and validate whether or not a user is in a particular group through the Object Context.  The method "IsCallerInRole" will check to see if that user is in the role (or group) you have created.  Based on the value returned you can use a simple if statement in the asp page and populate the values applicable to their security level.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Everyone has problem when going to load data into Data warehouse (EDW). They all need to confirm that data quality is good but they don't no how to proceed. Microsoft has provided new task within SSIS 2008 called "Data Profiler Task". It solve th…
Ever needed a SQL 2008 Database replicated/mirrored/log shipped on another server but you can't take the downtime inflicted by initial snapshot or disconnect while T-logs are restored or mirror applied? You can use SQL Server Initialize from Backup…
Using examples as well as descriptions, and references to Books Online, show the documentation available for date manipulation functions and by using a select few of these functions, show how date based data can be manipulated with these functions.
Via a live example, show how to extract insert data into a SQL Server database table using the Import/Export option and Bulk Insert.

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question